A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectiv
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Mul
In SAP Business One, sensitive information is written to the application�s memory dump files without obfuscation. Gainin
Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow
Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade I
The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational d
Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains a Cleartext Storage
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior,
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper
browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function o
Brocade SANnav before Brocade SANnav 2.4.0b logs database passwords in clear text in the standby SANnav server, after di
Brocade SANnav before 2.4.0b logs the Brocade Fabric OS Switch admin password on the SANnav support save logs. When OOM
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati
Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands,
IBM Planning Analytics Advanced Certified Containers 3.1.0 through 3.1.4 could allow a local privileged user to obtain s
When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return t
When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed TMOS Shell (tmsh) command that may allow a high
Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string
Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins co
A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function cre
A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file cor
Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secret
The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext o
In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could
In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run action
In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permissi
In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions c
In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run
In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permissio
In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could
In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with perm
In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission
In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could
In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could ex
In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" S
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7
A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packag
IBM Concert 1.0.0 through 2.1.0 stores potentially sensitive information in log files that could be read by a local user
A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an un
Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.
A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability i
A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext
The web server of the Access Manager offers a functionality to download a backup of the local database stored on the dev
With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinsta
Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data.
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mi
Frequently Asked Questions
What is CWE-312?
CWE-312 (CWE-312) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-312?
There are 230 CVE records associated with CWE-312 in our database. Of these, 16 are critical severity, 61 are high severity, and 95 are medium severity.
How can I protect against CWE-312 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-312 using AI-powered security agents.
Detect CWE-312 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-312 vulnerabilities across your infrastructure.
Get Started